Delve removed from Y Combinator
ycombinator.com
ycombinator.com
But that's just the cherry on top. I don't think they're being thrown out because they violated a license. There are really serious fraud allegations. Allegedly they were rubber-stamping noncompliant customers, leaving them exposed to potential criminal liability under regulations like HIPPA.
https://deepdelver.substack.com/p/delve-fake-compliance-as-a...
I've only skimmed this so I do not endorse these allegations, but I think it's context missing from this discussion.
I’m sure if Delve has only engaged in fraudulent audits or had only resold another YC company’s product, they would have been allowed to stay, the problem is all of that combined pissed off enough other YC companies.
Of course they're responsible for their investments; they're just not liable. YC has a lot to answer for in the damage it's wreaked over the years.
What damage is that? (excluding the present case)
That seems to be an introspective question.
They should pretty much die in a grease fire.
I find it unlikely, for example that there would not be a dominant centralized forum platform. People would have certainly started problematic communities on the dominant platform, and it's unlikely a platform with strict moderation would have gained dominance before 2015 or so. I do think a dominant player would have been established by 2015.
Do you think whatever you see as harmful about Reddit would not have occurred if the company didn't exist?
It would surprise me if the winner in that space didn't have a public voting mechanism. Digg, Reddit's early major competitor had one, and heavy-handed moderation surrounding the HD-DVD decryption key leak was one of the major inflection points that drove users from Digg to Reddit. Stricter moderation during that time period would have been a losing strategy.
The corporate shield for accountability is so annoying in this way. Nobody’s ever responsible for things that they did as human beings.
They thought it was a social bookmarking thing for people to find and share blog posts. It didn't even have comments for the first half year. For two more years, self-posts only existed as a hack where the poster had to predict the post's ID to make it link to itself. User-created subreddits didn't show up until about 2.5 years after the site launched.
I don’t really care to defend the morality of extremely wealthy VC firms like YC. They know the enshittification process that happens with 100% of the companies they fund.
They could create companies with charters and ownership structures that ensure they exist to better the world and make good products as their binding guiding principals, but they choose not to.
More fun with this subject: https://theonion.com/sam-altman-if-i-dont-end-the-world-some...
The delusions people establish to feel better about their or someone else they like mistakes...
Formally they might not be (depends on the case), but morally they are.
I'm seriously disgusted about this because this was one of the very few auditors that we held in pretty high esteem.
Pay-to-play is all too common, and I think that there is a baked in conflict of interest in the whole model.
Compliance gets taken quite seriously in an industry where one of your principal regulatory bodies has the power to unilaterally absorb your business and defenestrate your entire leadership team in the middle of the night.
I've seen this up close. The regulatory bodies as a rule are understaffed, overworked and underpaid. I'm sure they'd love to do a much better job but the reality is that there are just too many ways to give them busywork allowing the real crap to go unnoticed until it is (much) too late.
You can start very lightweight with doing spec driven development with the help of AI if you're at a size where you can't afford that. It's better than nothing.
But the important part is you, as a company, should inherently care.
If you rely on an auditor feedback loop to get compliant you've already lost.
It has the potential to be incredibly impactful, but often devolves into box ticking (like many compliance functions).
And it's really hard to find technical people to do the work, as it's generally perceived as a cost centre so tends not to get budget.
Like cool, it's a great idea and would potentially produce positive results if done well, but the roles pay half the engineering roles, and the interviews are stacked towards compliance frameworks.
There's very little ability to fix a large public company when HR is involved
I do agree that the pay isn't great, but it's the fact that it's considered a cost centre that's been the issue for me.
So many controls are dubious, sometimes even actively harmful for some set-ups/situations.
And even moreso, it's also perfectly feasible to pass the gates with a burning pile of trash.
Ook goeiemorgen...
We don't deal with the military though, only fintech (prime brokers and major banks, funds) some government. Plenty of certifications (have someone all site all year round),!no silliness.
I’ve been at companies where we cared deeply about security, but certain compliance things felt like gimmicks on the side. We absolutely wanted to to do the minimum required to check that box so we could get back to the real work.
None of those are likely.
This is the industry that missed Enron, WorldCom, Wirecard, Lehman, and many others.
Don't get me started. That hasn't even properly ended yet, the fall-out is continuing to today.
My response however is a simple one: I used to steer (a lot of) business their way and I have stopped doing that.
And no, I won’t whistleblow either, as it would mostly be me that would face repercussions, and I am unafraid to say that I am a coward.
We choose the battles we fight, and I’d like to believe that ultimately, entropy will defeat them without me lifting a finger.
There are thousands of companies where the shady practices are rewarded, the companies thrive and make money for the investors. So the investors are incentivized to reward this behavior just on the chance that they are rewarded back.
Whistleblowing sinks those chances and the investors and VCs know it. It doesn' just take away the money, it even takes away the plausible deniability. They put a lot of effort to absolutely punish any whistleblower to discourage the rest. Anything for a dollar. and this is probably all you'll ever need to know about almost every VC out there. Beyond the witty "I'm rich so I'm smart" blog posts and tweets, they're very much just the "anything for a dollar" type of people.
My lesson from the whole kerfuffle was that investors (at least the ones I’d dealt with) prefer hustle over integrity and execution abilities.
https://www.complexsystemspodcast.com/episodes/delve-into-co...
>Pre-written audit conclusions. The "Independent Service Auditor's Report" and all test conclusions were already filled in before clients had even submitted their company descriptions...
>Copy-paste templates. 493 out of 494 leaked SOC 2 reports (99.8%) had identical text, same grammatical errors, same nonsensical descriptions...
That's not the right metaphor here.
My usage was ironic. I don't think those fit my meaning because I think the situation would be largely the same without the licencing dispute.
I don't see how "they got caught doing X" is more complicated than "they got caught doing Y", but at any rate think it's worth being correct and precise in order to reason from accurate premises. If you absorb a lot of false information you'll start coming to incorrect conclusions and it'll be difficult to understand why. It took me years to unlearn all the bullshit I absorbed from when I used to spent a lot of time watching History channel documentaries.
> What for or how they got caught, does not matter.
So if they were ejected for jaywalking or for murder, that's all the same to you?
We have asked Delve to leave YC.
YC is a community, not just an accelerator. The founders in our community have to trust each other, and we have to trust them. When that trust breaks down, there's really only one thing to do.
We're not going to get into the details publicly. We wish them well.
https://x.com/___4o____/status/2040271468874076380I have no direct knowledge of the accuracy of any of this. This is not my account.
Considering they do due diligence before investment and are experts in IT and legal, how could they not know what is the business model when it was the unique selling point ?
Kinda like "bless your heart", which means nothing of the sort.
Maybe 7-8 years ago I met an Iranian. They were genuinely shocked I wasn’t a cowboy hat wearing racist when I told them I was from the south.
I grew up in the Atlanta area.
My comment is an internet comment about idioms, not a comprehensive linguistic treatise.
You seem like you're looking for something to be upset about. I wish you well.
For folks who don't know, here's the best explanation I can offer from growing up in the Atlanta area (but well outside the perimeter):
"Bless your heart" is most commonly an expression of sympathy.
Sometimes, it's sympathetic towards the hardship someone's going through (e.g. "and right after his grandma passed, bless his heart.")
Sometimes it's sympathetic to the trouble someone went through (e.g. "oh bless your heart, you didn't have to go out of your way to bring extra! Thank you so much!")
And yes, sometimes it's an expression of sympathy for the fact that life must be hard for you because of your ignorance, stubbornness, stupidity, or arrogance (or some other such stunting quality) (e.g. "and he thinks he can graduate from Tech with those grades, bless his heart," or "bless his heart, I just don't think he's ever had anyone tell him no in his entire life.")
It is often used an expression of thanks or appreciation, but I associate that more with an elder speaking to someone younger.
Most of the time, it is an genuine expression of true empathy, but it's not uncommon to be used as a passive aggressive expression of false empathy. It's that childish connotation that give it the extra bite when used passive aggressively.
And that plausible deniability, where the phrase is used in a genuine context often enough that sometimes you can't tell that someone is throwing shade, is very much a reflection of southern culture.
Source: Grew up in Georgia and North Carolina, with some family in Alabama.
That’s an oversimplification of what your parent comment said, which was someone who has betrayed your trust.
> It would be interesting if you didn't
Why? What’s interesting about it? You don’t have to actively wish harm on people who harmed you, but there’s nothing strange about not wishing them well.
We throw around words like "interesting", which is a subtle way to say "not normal", which is a subtle way to say that that's not how we would behave and that we think that others shouldn't behave that way either. So I take back what I said about what is interesting to me, and I'll just say that I wish it was normal to wish well to others, regardless of their actions or repercussions you impose on them.
Not what I said.
> To me the default posture is not indifference, but wishing wellness.
Same here. I’m not convinced that’s the default state for everyone, though. David Foster Wallace’s “This is Water” comes to mind.
> We throw around words like "interesting", which is a subtle way to say "not normal", which is a subtle way to say that that's not how we would behave and that we think that others shouldn't behave that way either.
Sure, I get that. Though you’re still answering as if what was in question was the neutral state of “people you don’t associate with” rather than the negative state in question mentioned by your original parent comment of “someone who has wronged you”.
> I'll just say that I wish it was normal to wish well to others, regardless of their actions or repercussions you impose on them.
Interesting. No criticism on my part. My wish would rather be that we don’t wrong each other (which, crucially, requires intentionality) in the first place. And while I don’t typically wish ill on others, I don’t think it’s wrong to not wish well on those who cause harm. If you’re a despot oppressing millions of people for your own selfish benefit, I don’t really think wishing you well is a positive action.
But again, no judgement, I was trying to understand your position, so thank you for clarifying. Have a nice weekend.
It looks like you've misinterpreted both what I said and what latexr said. Allow me to clarify and reorient the conversation back to the original direction...
First, neither of us is the universal subject. Your default feeling and my default feeling are not "the" default feeling. There's no such thing as "the" default feeling.
Second, nothing I or they said has anything to do with any "default passive state", because this is not a "default passive" situation. The word "betray" here is important. "Betrayal" happens actively, not passively. Feel however you want to feel about your passive default situations. This situation is different.
The only way someone can "betray" trust is by invalidating trust on purpose. If they harm you on purpose without trust, they have not betrayed any trust because there was none. If they invalidate trust accidentally, they have not "betrayed" the trust. They only "betray" your trust if you put trust in them and then they invalidate the trust intentionally.
> I'll just say that I wish it was normal to wish well to others, regardless of their actions
How very noble. Anyway, sorry Siddhartha, if someone actively "betrays" me they can go die in a fire. That has nothing to do with my "default passive" feeling about people.
I've not read Siddhartha. I take it you didn't like it.
As Donald Draper once said "I don't think about you at all."
What makes you say that wishes are finite? Do you ration them out to your loved ones?
That may not automatically mean you wish them harm in return, but I believe it would be very uncommon to not.
One way in which they do that is to ride or effectively are selected by the system for their mastery of the psychological trick of positivity and optimism that predisposes people to follow and trust, e.g., even when someone betrays you, you “wish them well.
In such systems, courage and hard lines that enforce strict rules, discipline, and principles does not provide the leaders in that system the affordances and benefits of leadership. As has been indicated, the subject behaviors are not only not novel, nor are they unique. What precipitated this current action appears to be the egregious and probably violative nature of the behavior, not the behavior itself. The veneer of perception was pierced, which is the real trigger of action.
Just use my saying what I just said above as an example, there will be people who have not even read this last paragraph and will it will have the urge to down vote what I said solely on the basis that they want to punish me, the messenger, because I’m pointing out things that are very much true and not saying it in a positive manner. It causes feelings of discomfort and especially in American society today where everything is geared towards positivity and good feelings opium, not bad feelings, even if you’re being scammed or defrauded or lied to, you have to remain positive, say things in positive ways, be “constructive”.
I don’t know if it’s sustainable because it’s such a con job at its very core, an abusive confidence trick, maintaining the perception of confidence and optimism to keep people happy and positive and optimistic regardless of red flags; however, we shall all find out one day if no one being able to deal with reality anymore if it’s not wrapped some nicety, is sustainable. Hence, “They violated us/me” but “I wish them well”. See, they are wished well, so everything is fine and we just removed the bad apple, nothing to see here, keep being positive as the telescreen instructs you to.
Trump On Ghislaine Maxwell: "I Just Wish Her Well" | NBC News
But Delve themselves can’t really do any of that. They’ve screwed up on a fundamental piece of their own business model. Their core offering *is* Compliance as a Service!
How could I trust their word that they’ll ensure my company is compliant? How could I trust their word that a company I’m doing business with is compliant? They can’t even handle their own Apache 2.0 licensed works, and that’s child’s play- relatively speaking. I’m supposed to trust that they can handle PCI and HIPPA and all the rest for other companies?
This is like having a dentist who doesn’t brush and floss their own teeth. Or a building inspector working out of a moldy office suite with exposed rebar. Or an editor with a personal website full of typos and grammatical errors. It’s a dealbreaker to anyone with common sense.
Unlike Zenefits, which had (allegedly?) committed fraud for part of their business in the interest of moving faster, and then Parker came back with Rippling…
These guys’ entire and actual business model was fraud.
the car was real, but there was no drivers licence. 'licence fraud' -> fraud
delve is an actual scam
If you can't trust your batch mates for something as crucial as compliance, the model doesn't work.
They scaled up massively the size of each batch and their frequency to a point where they are incapable of auditing them.
That looks like what happened here.
it's all just very strange and stupid, ironically from the the startup posing as auditors..
Shows the “compliance theatre” of what SOC2 has become
Every single technical auditor I've dealt with has been majorly incompetent and wanted to do things that would decrease security. And these were not some cheap bottom of the barrel companies but the big "industry leaders".
https://www.forbes.com/profile/delve/
30U30 never ceases to amaze.
Holmes, SBF, Shkreli, Charlie Javice, Ishan Wahi...
Hypercompetitive fields will always surface cheaters given enough time. Then regulations pile on to fight the cheating, which makes it harder for honest people to do the good work.
We do not punish cheaters like these as much as we should.
colour me surprised
people still seem to think that forbes scouts the world for the best talents instead of the lists being basically a paid ad
Not "Pay2Win" but possibly something less involved
Karma and integrity seem to be treated as an overdraft. But these folks are hardly held back by the systems they work in.
So, I'm fairly certain lists like that will attract some amount of unscrupulous narcissists.
Forbes MOST WANTED
This has zero bearing on equity, which would be a different conversation. In this case, I think the YC SAFE is likely to remain as-is, unless the founders choose to return the money, or YC chooses to levy a heavier allegation of fraud (which they don't seem to have done here).
And I don't think this is just not "getting locked out of the website", but losing the YC "nod" is a greater deal in itself
> Below are just some of the many inaccuracies in the story and then the truth.
> The Substack inaccurately said Delve relies on “Indian certification mills operating through front companies” and cannot pass legitimate audits. This too is not accurate.
At least it's not GPT but my goodness - you can definitely sense the panic. I think Karun is a little worried.
Notably YC hasn't wished them a farewell.
Why do all start-ups say this? I don't think there are many companies publicly saying "We're going to go 'scorched earth' on everybody."
Saying it in 2026 just makes it sound more insincere than usual.
> One interesting observation I’ve noticed is a lot of top founders did oddly strong at math from a young age.
https://x.com/kocalars/status/2027076198002553159
Nauseating.
Good riddance to bad rubbish.
https://delve.co/blog/delve-sets-the-record-straight-on-anon...
who got these kids into compliance? cause it wasn't them
Is there reason to believe that Delve has been removed from Y Combinator, the organization, or is this more an announcement that Delve has been removed from Y Combinator's website?
And please stop investing in slop/wrappers. They do not solve World's problems.
I feel there has been complacency set into investing in general where investors are chasing quick money (first crypto and now AI slop) over solving hard/grueling problems that take a long time to fix but have huge returns down the line.
And we have a lot of tough problems that still need solving. AI won't magically fix that, despite being a great tool.
YC since then seems to have moved into a "spray and pray" approach where the ideas don't matter at all, they're 150% in on the "We invest in founders" idea now, almost too much, although I know that's always been a thing they've thought about. But all the batches since some years ago are just so uninspired and seem to be quick cash grabs, or obviously acquisition targets, rather than "solve a problem you experience yourself" which seemed to be much more popular (and realistic) before.
It means everything for YC's model.
YC does not care about the software.
They care about the founders.
YC's model and ecosystem is explicitly designed to be a who's who club of interconnected founders that are very, very encouraged to """rely""" on each other when building their companies.
YC uses a lot of double speak regarding this ecosystem, but if you explained the concept to a layman on the street they'd tell you exactly what this concept is in just a very few, very blunt words.
Elite-class founders and lots of cheap, imported, or "passionate" labor.
Let's get real here folks.
yc is explicitly an imitation of harvard , right down to calling people 'alumni'
this is how to find supertalent. much like american idol it works well but not for everyone
Also, there was no “endgame.” They weren’t trying to change the law; they were exclusively breaking it for profit.
But I agree that Delve is a special case and should naturally be held to a higher standard here because their whole business is around being compliant with the law. When most other startups break the law, they do it to get an advantage over competition. Delve did it in a way that sacrificed their core value towards customers.
this will literally get them in court
Huh? In a legal sense I'm pretty sure they're the same thing.
How and why matters, though.
How and why you break a law matters (to a judge / jury). Whether you frame it as "ignoring" vs "breaking" in your legal defense, not so much.
> I ignore the law every day when I jaywalk.
Means the exact same thing as “I intentionally break jaywalking laws every day”. They are equivalent sentences.
Not illegal here, but I hope you not complain when caught and fined.
Including people doing it in front of police. Including the police themselves!
The law only existed for police to harass and fine blacks and Latinos. And indeed, that was how it was struck down.
It is critical to a just society that victims of unjust laws or uneven enforcement complain!
This is something Airbnb has facilitated for a very long time, no? And Uber, back when it started.
From a legal perspective I don’t see that it matters whether you’re trying to change the law or not. You’re either following it or breaking it.
In reality, it makes quite a difference if public opinion is on your side or not.
“We decided to commit fraud by providing fake compliance reports” reads very differently from “we let homeowners make money by renting a room”
This is like a line from a Naked Gun movie. The only way that this sentence could be true linguistically is if the party doesn’t break the law that they’re ignoring (e.g. I could ignore the rule against perpetuities while drunk driving through a zoo)
Like, it's a company that sells AI-slop powered regulatory compliance. How many laws do you think the "fake it ill you make it and you'll never make it" AI will break? But "regulatory compliance" is laws that startups hate, so breaking them is good.
Copyright and the copyleft licenses built upon it are the laws that support the software industry instead of just making sure innocent people aren't hurt by all this innovating and disrupting.
Anderson Consulting er I mean "Accenture": "Hey, that's our job!"
PWC: "Yeah! Fuck off!"
KPMG: "Damn straight!"
Ernst & Young: "What they said."
Deloitte & Touche: "Ditto."
( https://en.wikipedia.org/wiki/Accounting_scandals#List_of_th... )
...is breaking the law
1. Customers want to do something, you help them do it, but it's illegal.
2. Customers want to do something, you tell them you did it, but you were lying and defrauding them.
3. Customers want to do something, you help them do it, and nobody has done it before, so whether it's legal or not is kind of up in the air.
E.G. Uber exploited a legal loophole that distinguished the kind of taxi service you hail on the street from the kind of taxi service you call on a phone.
The latter were much less regulated, and usually much more exclusive and pandering to a richer crowd. Nobody really knew which kind Uber should be classified as, it was the first kind in practice (same customer base as normal taxis) but the second in theory (ordered, not hailed).
It is clearly different because in one case you are not guilty of fraud.
Being guilty of a crime plus fraud is obviously worse than just being guilty of the crime.
Breaking the law by stealing a loaf of bread is obviously different to killing one million people but "both boil down to breaking the law" - I'm not sure that comment contains that much information.
Their value prop had to be strong enough to get past YC, past the other founders in the batch, past due diligence. Given that, I'm no longer comfortable casting "fraud" as a clean binary.
To be clear — I do genuinely believe they are a fraudulent company that lied and deserved to be removed. But introspectively, I have to sit with the fact that the space between "working around dumb regulations" and "outright fraud" is murkier than we'd like to admit.
They claimed to have a working product and a big list of paying clients while in fact they had a half-assed prototype written by one hapless dude who they paid to the tune of $15 an hour. Which i helped to transform into a somewhat-better prototype and they paid very well for it. But no actual paying clients ever existed and the idea was obviously brain-dead from day one. After they got tired of pretending, they stopped paying, then disappeared. Then years later i read in the news that subsequent investors launched an investigation into fraud and they were put on the list in some countries.
I'm sure no one except themselves ever made any money on it, certainly not YC.
"delve removed from y combinator" removed from y combinator
The only next product launch is an investigation.
Post now seems deleted.....
Well, can see why...if its fraud you only post it when results of investigation by 3rd party is in due to defame concerns...
->
You mean like OpenAI, Anthropic and all these other 'unicorns'?
I'm happy we're all clear on how bad Delve is but in essence what they were doing is exactly the same as what these AI companies do.
I'd wager there's some prior art...
The specific fraud allegations are bad (lying about US based auditors) but it's completely normal and common for soc2 reports to be templates with no company specific information. It would be unusual for reports to include anything about the specific information found during an observation window as some have suggested.
SOC2 is basically fake and it isn't possible in practice to fail to be compliant. You really can apply the same template to all companies and automate the audit process.
- proving churned customer data was deleted completely and within the agreed-on period of time
- - not enough to have a record
- - auditors will ask you to prove the data is not laying around
- proving all changes shipped are reviewed and linked to tracked work- proving branch rules are set to require PRs and prohibit changing history on release/trunk branches
- - auditors will ask you to show live that you can’t approve your own changes
- - some auditors might ask you for an audit log to prove no unexpected branch rule changes occurred —- depending on the observation period, you might have to build your own audit log capture to prove this
- proving you performed penetration testing- proving you performed a disaster recovery test in production with the frequency you claim (e.g. annually)
- - running a DR test might be more than a few hours depending on your data size and level of infra automation
- - this is often something that startups are ready to execute, but don’t invest a lot of time automating
- proving you have and enforce full-disk-encryption on all your employee laptops - - this is automated with MDM but a startup might not be running an MDM yet
- proving you are rotating credentials on the frequency you ascribe to in your policies - - automated reports are available for some credentials, e.g. AWS keys, but takes more work for smaller vendors
- - even with AWS, you might discover you forgot to rotate something, and it might be because it’s non-trivial to execute
- perform quarterly access reviews - - some systems are more difficult/time consuming to inspect against your employee and permissions list
- - ideally this is automated, but often times at a startup, you might not have fully automated authorization and access control, such that when employees change teams or leave the company, that you get notified and don’t miss it
- proving that you act on performance or reliability alerts - - auditors will ask you to show live some examples of past alerts and that someone handled it
- - auditors will often ask you to show live that these alerts are consistently configured for all your production system —- startups might not have the alerting and PagerDuty-like setup be fully automated (e.g. with Terraform)It's pretty simple. Compliance is legally important, and faking compliance exposes companies to extraordinary legal liability. Being lied to about your compliance warrants outrage.
>SOC2 is basically fake
This isn't true, but if it were, it would justify outrage in its own right.
And yes SOC2 is fake. Have you ever heard of a startup failing to get soc2 or doing more than a few hours of work to get into compliance?
Y Combinator as a concept, and all of its "children" are rotten to the core.
Every single company is "evil" in some form, and not in the usual "private companies are big baddies" kind of way. They grossly and recklessly violate laws and ethical boundaries day in and day out.
The sooner people are even willing to entertain this, the sooner we can have actual conversation around these issues.